logo

Security Alert: Cemu Emulator Linux Releases Compromised via GitHub Backdoor (May 2026)

ID: 260c963b-a303-5d37-aefb-3dee2a4594e3

STIX ID: report--260c963b-a303-5d37-aefb-3dee2a4594e3

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-05-13

Date Updated: 2026-05-13

Author: Ddos

...
...

Cemu published a security bulletin: an attacker used a poisoned Python package to steal a developer's GitHub API tokens and push backdoored Linux release binaries (Cemu-2.6-x86_64.AppImage and cemu-2.6-ubuntu-22.04-x64.zip) between 2026-05-06 and 2026-05-12. The embedded backdoor stealthily exfiltrates credentials and environmental secrets, skips execution on systems using Russian language, and attempts destructive 'rm -rf/' behavior on systems identified as located in Israel; users who downloaded and ran the compromised installers are advised to perform full OS reinstalls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.